source-driven-development

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest data from external sources such as documentation URLs and web search results. This creates a surface for indirect prompt injection if a third-party website contains malicious instructions intended to manipulate the agent's behavior. However, this is a theoretical risk inherent to web-enabled agents and is mitigated here by the lack of any automated execution capabilities within the skill itself.
  • Ingestion points: Local dependency files (package.json) and external documentation websites retrieved via URL or web search.
  • Boundary markers: The skill does not define specific delimiters for external content but encourages verifying claims against authoritative sources.
  • Capability inventory: The skill contains no scripts, executable tools, or filesystem-write operations. It is purely instructional.
  • Sanitization: No explicit sanitization or filtering of external content is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 09:19 AM
Security Audit — agent-trust-hub — source-driven-development